An improved authentication with key agreement scheme on elliptic curve cryptosystem for global mobility networks

被引:16
|
作者
Li, Xuelei [1 ]
Wen, Qiaoyan [1 ]
Zhang, Hua [1 ]
Jin, Zhengping [1 ]
机构
[1] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100876, Peoples R China
关键词
USER AUTHENTICATION; PROTOCOL;
D O I
10.1002/nem.1827
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we cryptanalyze Rhee et al.'s 'Remote user authentication scheme without using smart cards', and prove that their scheme is not completely secure against user impersonation attack. The security flaw is caused by mathematical homomorphism of the registration information. In addition, their scheme lacks key agreement procedures for generating the session key to encrypt the communication messages after mutual authentication. Furthermore, a modification is proposed to improve the security, practicability and robustness of such scheme. Firstly, we introduce elliptic curve cryptosystem to enhance the security. Secondly, in order to improve the practicability, our improvement is much more easily implemented using portable devices in global mobility networks; moreover, a synchronized clock system, traditional password table or ancillary equipment are not required in our improvement. Finally, the proposed scheme not only achieves mutual authentication, but also provides the procedure for key agreement and update of secrets for users and servers to increase the robustness. Copyright (c) 2013 John Wiley & Sons, Ltd.
引用
收藏
页码:311 / 324
页数:14
相关论文
共 50 条